Seit ein paar Tagen meldet mir KeyHelp dass fuer eine Domain das SSL Zertifikat nicht erneuert werden kann.
Die Domain des Kunden liegt bei IONOS und dort hat er lediglich die Nameserver fuer die Domains hinterlegt, die DNS Verwaltung findet hier auf dem Server statt. Bisher gab es nie Probleme mit der Ausstellung des Zertifikats...
alle Pruefungen die man dann so macht sind ok... Wo koennte es haken?
Code: Select all
------------------------------------
Certificate name: works-stratos.uk (Let's Encrypt)
Verification ended with an error.
Details: During secondary validation: DNS problem: SERVFAIL looking up A for works-stratos.uk - the domain's nameservers may be malfunctioning; DNS problem: SERVFAIL looking up AAAA for works-stratos.uk - the domain's nameservers may be malfunctioning
Type: urn:ietf:params:acme:error:dns
Full response: {"type":"http-01","url":"https:\/\/acme-v02.api.letsencrypt.org\/acme\/chall\/1822069087\/584619823491\/u_dFFQ","status":"invalid","validated":"2025-09-17T04:01:06Z","error":{"type":"urn:ietf:params:acme:error:dns","detail":"During secondary validation: DNS problem: SERVFAIL looking up A for works-stratos.uk - the domain's nameservers may be malfunctioning; DNS problem: SERVFAIL looking up AAAA for works-stratos.uk - the domain's nameservers may be malfunctioning","status":400},"token":"jkFlYH174LPsNsq6k5g8KuI57SG8pu0QFJ2IVUwLFrQ","validationRecord":[{"url":"http:\/\/works-stratos.uk\/.well-known\/acme-challenge\/jkFlYH174LPsNsq6k5g8KuI57SG8pu0QFJ2IVUwLFrQ","hostname":"works-stratos.uk","port":"80","addressesResolved":["46.38.245.28","2a03:4000:b:ba:78f8:caff:fe33:9c9b"],"addressUsed":"2a03:4000:b:ba:78f8:caff:fe33:9c9b"},{"url":"https:\/\/works-stratos.uk\/.well-known\/acme-challenge\/jkFlYH174LPsNsq6k5g8KuI57SG8pu0QFJ2IVUwLFrQ","hostname":"works-stratos.uk","port":"443","addressesResolved":["46.38.245.28","2a03:4000:b:ba:78f8:caff:fe33:9c9b"],"addressUsed":"2a03:4000:b:ba:78f8:caff:fe33:9c9b"}]}
Valid until: 2025-10-04 05:02:40 (16 day(s) left)
Certificate name: www.works-stratos.uk (Let's Encrypt)
Verification ended with an error.
Details: Unable to validate JWS :: JWS has an invalid anti-replay nonce: "1ZGyytInNDAoIfNWwYoOFCqYDR56rlDNiZEf-l2_w_iPiLYPDcM"
Type: urn:ietf:params:acme:error:badNonce
Full response: {"type":"urn:ietf:params:acme:error:badNonce","detail":"Unable to validate JWS :: JWS has an invalid anti-replay nonce: \"1ZGyytInNDAoIfNWwYoOFCqYDR56rlDNiZEf-l2_w_iPiLYPDcM\"","status":400}
Valid until: 2025-10-04 05:02:50 (16 day(s) left)
------------------------------------
